bb-huge 🤗 , Personal bug bounty findings hub and bug bounty orchestration for multiple agents
-
Updated
Jul 11, 2026 - Python
bb-huge 🤗 , Personal bug bounty findings hub and bug bounty orchestration for multiple agents
CTF and Bug Bounty Hunting WriteUps.
Writeups from PicoCTF challenges across different categories such as Cryptography, Web Exploitation, Reverse Engineering, and more.
CSRF toolkit - token analysis, request forgery and protection validation.
Webshell generator - obfuscated PHP/ASP/Java shells and detection-evasion demos for labs.
SSTI scanner - template-engine fingerprinting and payload injection for template flaws.
Directory brute-forcer - hidden endpoint and backup-file discovery with wordlists.
Master cybersecurity skills with this TryHackMe free path, includes a collection of my write-ups, solutions and progress tracking.
Web subdomain sweeper - name resolution, wildcard detection and takeover checks.
XSS scanner - payload fuzzing, context-aware detection and CSP-bypass checks.
CORS misconfiguration scanner - origin validation and preflight-response flaw detection.
XXE injection toolkit - entity expansion, blind-OOB exfiltration and parser hardening tests.
Browser exploitation lab - DOM-based attacks and client-side defense exercises.
SQL injection automation suite - detection, extraction and exploit scaffolding for sqli labs.
HTTP request-smuggling tester - CL.TE/TE.CL desync payload validation.
CMS vulnerability scanner - plugin/theme version fingerprinting and known-CVE matching.
PicoCTF-Writeup: A collection of solutions and writeups for PicoCTF challenges, documenting problem-solving steps and techniques.
Solutions and write-up for 2025 PicoCTF competition
To associate your repository with the webexploitation topic, visit your repo's landing page and select "manage topics."